SB2018090614 - Privilege escalation in Cisco Webex Meetings Client
Published: September 6, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Privilege escalation (CVE-ID: CVE-2018-0422)
The vulnerability allows a local attacker to gain elevated privileges on the target system.
The vulnerability exists in the folder permissions due to folder permissions that grant a user the permission to read, write, and execute files in the Webex folders. A local attacker can write malicious files to the Webex client directory, affecting all other users of the targeted device and execute commands with elevated privileges.
Remediation
Install update from vendor's website.